Pentest-AI
Project policies

Acceptable use

Use Pentest-AI only within an explicitly authorized testing scope.

Updated 12 September 2026

Obtain explicit authorization

Run Pentest-AI only against systems you own or have permission to assess. Agree on the target list, test identities, allowed methods and operating limits before starting. A public hostname is not an invitation to test it.

Stay within scope

  • Do not bypass the tool's scope checks or use it to reach systems outside the agreed engagement.
  • Do not use it to steal credentials, access private information without permission, deploy malware, extort people or disrupt a service.
  • Use only test accounts and data permitted by the engagement.
  • Stop when unexpected access or sensitive data is encountered and contact the responsible owner.
  • Respect third-party terms, operating limits and applicable law.

Handle evidence carefully

Reports and capsules may contain private routes, response details or sensitive information. Minimize collection, restrict access and retain evidence only as appropriate for the engagement. Do not place private evidence in public issues or unrestricted CI artifacts.

Report abuse and defects

For a vulnerability in Pentest-AI, use the private reporting channel. For concerns about misuse connected to the project, email [email protected] with the relevant context. Do not send stolen data or credentials as proof.

This guidance does not change the software's MIT licence or grant authorization from a target owner.

Found something unclear?Open an issue ↗